hacker-news · Crawled Jul 19, 2026

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

1 IoCs 1 Actors
Read original article ↗

AI Summary

Russian state-sponsored threat actor UAC-0145, a sub-cluster of Sandworm affiliated with GRU, has been conducting cyberattacks against Ukrainian targets using the ClickFix social engineering technique. The attackers compromise websites and inject fake CAPTCHA checks that prompt users to execute malicious PowerShell commands, leading to malware infection. These commands download and execute malware such as GHETTOVIBE, SCOUTCURL, and COWARDDUCK, enabling data theft and remote control. The campaign also involves backdooring Android devices via malicious APKs distributed as security tools.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 1 extracted

Type Value Detail
Filename GHETTOVIBE Details →

MITRE ATT&CK TTPs 17 techniques